Skip to the Base64 decoder

RFC 4648 §5 · base64url

Base64URL decode, padding and all.

Paste URL-safe Base64 — from a JWT, a URL parameter, a WebAuthn challenge or the Gmail API — and it is decoded with - and _ mapped back and the missing = padding restored. Paste a whole JSON Web Token and the header and payload are unpacked into a table.

Updated · Runs entirely in your browser

Base64URL decode converter

0 chars
Decoded result
Type: — Size: 0 B
Options
General
Decoding options

Ctrl+Enter decode Ctrl+Shift+C copy result Drop a file anywhere on the input to load it

How to decode Base64URL

  1. 01

    Paste the base64url value

    Paste a URL-safe Base64 string or a complete JWT. The - and _ characters and the missing padding are handled automatically.

  2. 02

    Read the decoded result

    Plain values are decoded to text or bytes. A JWT is split into its header and payload, with iat, nbf and exp shown as dates.

  3. 03

    Copy or keep decoding

    Copy the JSON, format it, or press Send to input if the payload contains another encoded value.

Base64 vs. Base64URL

Standard Base64 uses + and /, which mean something in URLs and file names, and pads with =, which has to be percent-encoded in a query string. Base64URL, defined in RFC 4648 section 5, swaps just those characters so the value can travel in a URL untouched:

Differences between standard Base64 and Base64URL
Base64Base64URL
Value 62+-
Value 63/_
Padding= requiredusually omitted
Defined inRFC 4648 §4RFC 4648 §5

The other 62 characters are identical, so converting is a simple character swap plus padding.

Restoring the missing padding

Many strict decoders reject unpadded input. The rule for putting the padding back depends only on the length of the string modulo 4:

  • remainder 0 — no padding needed;
  • remainder 2 — add ==;
  • remainder 3 — add =;
  • remainder 1 — impossible in valid Base64: the value is truncated.

This decoder applies the rule for you and reports a truncated value instead of silently returning garbage.

Where you meet base64url

  • JSON Web Tokens — the header, payload and signature are three base64url segments joined by dots. The signature is shown but not verified, since that needs the key.
  • WebAuthn and passkeys — challenges, credential IDs and client data.
  • OAuth PKCE — the code_challenge is a base64url SHA-256 digest.
  • Gmail API — message bodies and attachments are base64url encoded.
  • Short IDs and tokens in URLs, cookies and file names.

Decode base64url in code

# Python: urlsafe_b64decode still needs the padding back
import base64
def b64url_decode(s: str) -> bytes:
    return base64.urlsafe_b64decode(s + "=" * (-len(s) % 4))

// Node.js 16+
Buffer.from(token, "base64url").toString("utf8");

// Go
base64.RawURLEncoding.DecodeString(s)

// Java 8+: the URL decoder accepts unpadded input
Base64.getUrlDecoder().decode(s);

For standard Base64 and more languages, see the main Base64 decode page.

More decoders

Other ways to decode Base64.

Questions

Base64URL decode: common questions.

How do I decode Base64URL?

Replace - with + and _ with /, add = padding until the length is a multiple of four, then decode as normal Base64. This page does all three automatically: paste the value and the decoded result appears immediately.

Is Base64URL the same as URL encoding?

No. URL encoding (percent-encoding) escapes individual characters as %XX. Base64URL is a variant of Base64 that converts bytes to a URL-safe alphabet. If a value contains %2B or %3D, it is percent-encoded Base64; decode the percent-encoding first.

Can I decode a JWT with this tool?

Yes. Paste the whole token and the header and payload are decoded from base64url and shown as a table, with timestamps converted to dates. The signature is displayed but not verified, because that requires the secret or public key.

Why does Python raise “Incorrect padding” on base64url input?

base64.urlsafe_b64decode expects the = padding that base64url usually omits. Append "=" * (-len(s) % 4) to the string before decoding, as in the snippet on this page.